A website enquiry creates a data-handling task. The review needs to cover the information collected, its purpose, who receives it and what happens after the message arrives. A privacy notice is one part of that process.
This article is general information. Apply it with advice appropriate to your business, especially where health information or other sensitive data is involved.
Map the actual route
List every place the site collects information: contact forms, bookings, newsletter sign-ups, analytics and third-party embeds. Then record the providers and people who can access it.
Use this inventory when reviewing your obligations under the Protection of Personal Information Act. A form that sends to a third-party service should not be described as if information remains only on your own server.
Ask for what the task needs
For an initial enquiry, consider whether the name, reply address and message are enough. Make optional fields clearly optional. Avoid adding identification or clinical fields without a defined need and appropriate controls.
The collection purpose, lawful basis, security and retention arrangements should be considered together. Adding a consent checkbox does not by itself complete the review.
Keep the notice accurate
Check that your privacy notice reflects the tools and workflow in use. Explain the purpose of collection and provide a route for privacy enquiries. Review the notice when your providers or processes change.
Separate an enquiry from any decision to add someone to marketing. The Information Regulator publishes guidance on direct marketing; use that guidance for the relevant workflow.
Assign responsibility
The Information Regulator provides guidance on Information Officers and registration. Confirm who is responsible in your organisation and how requests are handled.
Separately review the PAIA manual requirements and the Regulator’s resources. A public-facing website should make the applicable information easy to find.
Check the operation after launch
Review access to form submissions, mailbox security, retention and deletion practices. Test the enquiry route without using real sensitive records. Repeat the review when adding a new integration.
A technically sound site supports the process, but does not establish legal compliance on its own. Keep decisions documented and refer matters outside the website team’s expertise to an appropriate adviser.
Next step: request a free Website Check, or see Baken’s medical practice websites.